F-Secure: Be Sure
Main
F-Secure Logo - Be Sure
Select local site


Privacy Policy
Legal Notices
Contact Us

F-Secure Virus Descriptions : Welchi

[Summary] | [Disinfection] | [Detailed Description] | [Detection]

THIS VIRUS IS RANKED AS LEVEL 2 ALERT UNDER
F-SECURE RADAR.

Radar Alert LEVEL 2

NAME:Welchi
ALIAS:Nachi, Welchia, WORM_MSBLAST.D, Sachi
SIZE:10240

Summary

Another new RPC worm was found on August 18th 2003.

This variant is functionally similar to Lovsan. It uses two known vulnerabilities to infect unprotected systems. This worm will disinfect Lovsan.A and attempt to patch the machine with the fix made available by Microsoft.

Disinfection

Disinfection Tool

F-Secure provides the special tool to disinfect the Welchi worm. The tool and disinfection instructions are available at:

ftp://ftp.f-secure.com/anti-virus/tools/f-welchi.zip

ftp://ftp.f-secure.com/anti-virus/tools/f-welchi.txt

ftp://ftp.f-secure.com/anti-virus/tools/f-welchi.exe

ftp://ftp.f-secure.com/anti-virus/tools/f-welchi.jar

You can also use our webserver to download the tools:

http://www.f-secure.com/tools/f-welchi.zip

http://www.f-secure.com/tools/f-welchi.txt

http://www.f-secure.com/tools/f-welchi.exe

http://www.f-secure.com/tools/f-welchi.jar

Please, note that this worm creates a Service activating the legitimate windows tftp server. This Service won't be stopped, and the legitimate (although renamed) tftp server won't be deleted using FSAV disinfection capabilities alone. To remove the service, use the disinfection tool. The renamed server can be manually deleted from the machine. Its location has been previously given in this description.

Disinfection

As it's mentioned in the virus, the worm will stop working when the computer's clock is set to 2004. So, this feature can be used to remove it from the computer.

This can be automated with the date and the shutdown commands, for example:

 DATE 01-01-2004
 SHUTDOWN -r


Back to the Top


Detailed Description

This variant uses files named DLLHOST.EXE and SVCHOST.EXE which is a tftp server. Note that DLLHOST.EXE and SVCHOST.EXE are names of normal Windows system files.

Those files can be found in the following locations in an infected machine:

The worm file:

 %systemDir%\wins\DLLHOST.EXE

The renamed tftp server:

 %systemDir%\wins\SVCHOST.EXE

It infects computer using the same vulnerability as the Lovsan worm. Please refer to Lovsan's description for instructions on patching the security hole:
http://www.f-secure.com/v-descs/msblast.shtml

In addition, Welchi will attempt to infect IIS 5.0 web servers via WebDAV exploit. For more on this vulnerability found in March 2003, see:
http://www.microsoft.com/technet/security/bulletin/MS03-007.asp

Welchi only infects Windows XP machines through the RPC hole and both Windows 2000 and XP machine through the WebDAV hole.

It also tries to disinfect Lovsan.A from the machine and apply the Microsoft patch to close the RPC hole. For doing so it will attempt to download the patch from eight different URLs, corresponding to four language versions (English, Chinese, Simplified Chinese and Korean) for both Windows XP and 2000.

Do note that Welchi doesn't always install the patch successfully. We recommend that after cleaning Welchi you'd double-check the patch according to the instructions from Microsoft (see the section File Information):
http://support.microsoft.com/?kbid=823980

When trying to disinfect Lovsan.A it will look for a process with the strings "msblast" in its name and will proceed to terminate it if found. Then it will delete the file under the path

 %systemdir%\msblast.exe

So, Welchi is an anti-virus-virus.

When run, it will create a mutex named "RpcPatch_Mutex", so there's always only one active copy of the worm.

Apparently the worm does not modify the Windows Registry as to be launched automatically.

It contains the string, which is never displayed:

 =========== I love my wife & baby :)~~~  Welcome Chian~~~
 Notice:  2004 will remove myself:)~~ sorry zhongli~~~====
 =======  wins


Back to the Top


Detection

[FSAV_Database_Version]

Version=2003-08-18_03


Back to the Top


[Description: Mikko Hypponen and Ero Carrera; 18th of August, 2003]